Federal · Title 10 — Armed Forces

10 U.S.C. § 428: Defense industrial security

Read the full statutory text
The Secretary of Defense shall be responsible for the protection of classified information disclosed to contractors of the Department of Defense. The Secretary shall carry out the responsibility assigned under subsection (a) in a manner consistent with Executive Order 12829 (or any successor order to such executive order) and consistent with policies relating to the National Industrial Security Program (or any successor to such program). The Secretary may perform industrial security functions for other agencies of the Federal government upon request or upon designation of the Department of Defense as executive agent for the National Industrial Security Program (or any successor to such program). The Secretary shall prescribe, and from time to time revise, such regulations and policy guidance as are necessary to ensure the protection of classified information disclosed to contractors of the Department of Defense. The Secretary shall ensure that sufficient resources are provided to staff, train, and support such personnel as are necessary to fully protect classified information disclosed to contractors of the Department of Defense. is sponsored for a facility clearance; is provided access to sensitive compartmented information facilities and classified networks where the member can perform classified work; and not less than quarterly, is invited to in-person meetings with relevant personnel of the Department of Defense to discuss classified information. an assessment of any existing related efforts to increase sensitive compartmented information facilities and how such efforts might be accelerated and elevated in priority; target metrics for increased facility clearances in association with membership in the collaborative forum described in subsection (a) or to companies awarded contracts in accordance with Executive Order 12968; an identification of any additional funding or authorities required to support increased processing of facility clearances; and any other matters the Secretary of Defense considers relevant.” to expand access to secret or collateral accredited facilities and sensitive compartmented information facilities and special access program facilities to securely perform work under existing classified contracts; to reduce the cost and administrative requirements for a facility to receive and maintain accreditation and certification as an accredited facility; to increase opportunities for small business concerns and institutions of higher learning to have access to and compete for classified contracts; and to identify policy barriers that prevent components of the Department of Defense from more broadly using shared classified commercial infrastructure and prototyping proposed solutions. The Secretary shall designate an existing civilian official of the Department of Defense who shall be responsible for the administration of the pilot program established under subsection (a). for access for contractors and components of the Department of Defense to shared classified commercial infrastructure; and to facilitate the use of such infrastructure by covered small business concerns and institutions of higher learning. In consultation with the Office of the Director of National Intelligence, to coordinate with the Director of the Defense Counterintelligence and Security Agency, the Director of the Defense Intelligence Agency, and the Director of the Defense Information Systems Agency to update or prescribe policies and regulations governing the process and timelines pertaining to how shared commercial classified infrastructure may obtain relevant facility authorizations and access to secure information technology networks from the Department of Defense. To make recommendations to the Secretary of Defense regarding the modernization, streamlining, and acceleration of the approval process of the Department of Defense for contacts, subcontracts, and co-use or joint use agreements for shared classified commercial infrastructure. The development and maintenance of metrics tracking the outcomes of each request made under the pilot program for the accreditation of shared commercial classified infrastructure as an accredited facility. As part of the pilot program established under subsection (a), the Director of the Defense Counterintelligence and Security Agency, the Director of the Defense Intelligence Agency, and the Director of the Defense Information Systems Agency shall each update or prescribe policies and regulations governing the processes and timelines pertaining to how shared commercial classified infrastructure may obtain relevant facility sponsorship, associated authorizations and accreditation, and access to relevant secure information technology networks from the Department of Defense. The Secretary of Defense shall ensure that the pilot program established under subsection (a) includes efforts to modernize, streamline, and accelerate the approval process of the Department of Defense for shared, co-use, and joint use agreements to facilitate the access of small business concerns and institutions of higher learning performing under contracts or other agreements with the Department to classified environments. after the establishment of such pilot program, but not later than two years after the establishment of such pilot program; and after the termination of such pilot program pursuant to subsection (e), but not later than 120 days after such termination. A list of each request made under the pilot program for the accreditation of a facility as an accredited facility, including the date on which the request was made to the civilian official designated under subsection (b) and to the relevant facility accreditation agency. A list of the total number of personnel authorized to conduct inspections under the pilot program for the accreditation and certification of facilities as accredited facilities. Actions taken by the civilian official designated under subsection (b) to streamline the process of the Department of Defense for approval of co-use and joint use agreements to facilitate the access of small business concerns and institutions of higher learning performing under contracts or other agreements with the Department to classified environments, including any updated or new policies or guidance issued as a result of the pilot program. A list of all unutilized and currently accredited sensitive compartmented information facilities owned and operated by the Department of Defense that are located within 25 miles of a facility described in subsection (a)(1). A list of the metrics or other measures used by the Department of Defense to assess the benefits to the Department from the pilot program established under subsection (a), and any other metrics the Secretary of Defense deems appropriate. The authority to carry out the pilot program required by subsection (a) and the requirements of this section shall terminate on September 30, 2030 . The term ‘institution of higher learning’ has the meaning given such term in section 3452(f) of title 38 , United States Code. The term ‘shared commercial classified infrastructure’ means fully managed, shared, classified infrastructure (including physical facilities), and associated services that are operated by a private third-party for the benefit of appropriately cleared government and contractor personnel who have limited or constrained access to secret collateral and sensitive compartmented information facilities. The term ‘small business concern’ has the meaning given such term under section 3 of the Small Business Act ( 15 U.S.C. 632 ).” shall establish and implement a pilot program for oversight of designated Department of Defense controlled unclassified information in the hands of defense contractors with foreign ownership, control, or influence concerns; and may designate an entity within the Department to be responsible for the pilot program under paragraph (1). The use of a capability to rapidly identify companies subject to foreign ownership, control, or influence that are processing designated controlled unclassified information, including unclassified controlled technical information. The use, in consultation with the Chief of Information Officer of the Department, of a capability or means for assessing industry compliance with Department cybersecurity standards. A means of demonstrating whether and under what conditions the risk to national security posed by access to Department controlled unclassified information, including unclassified controlled technical information, by a company under foreign ownership, control, or influence company can be mitigated and how such mitigation could be enforced. By not later than 30 days after the completion of the pilot program under this section, but in no case later than December 1, 2019 , the Secretary shall provide to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a briefing on the results of the pilot program and any decisions about whether to implement the pilot program on a Department-wide basis.” In order to facilitate access for small business concerns and nontraditional defense contractors to affordable secure spaces, the Secretary of Defense, in consultation with the Director of National Intelligence, shall develop processes and procedures necessary to build, certify, and maintain certifications for multi-use sensitive compartmented information facilities not tied to a single contract and where multiple companies can securely work on multiple projects at different security levels. The term ‘small business concern’ has the meaning given that term under section 3 of the Small Business Act ( 15 U.S.C. 632 ). The term ‘nontraditional defense contractors’ has the meaning given that term in section 2302 of title 10 , United States Code [now 10 U.S.C. 3014 ].” The Secretary of Defense shall develop a plan to ensure that covered entities employ and maintain policies and procedures that meet requirements under the national industrial security program. In developing the plan, the Secretary shall consider whether or not covered entities, or any category of covered entities, should be required to establish government security committees similar to those required for companies that are subject to foreign ownership control or influence mitigation measures. to which the Department of Defense has granted a facility clearance; and that is not subject to foreign ownership control or influence mitigation measures. The Secretary of Defense shall issue guidance, including appropriate compliance mechanisms, to implement the requirement in subsection (a). To the extent determined appropriate by the Secretary, the guidance shall require covered entities, or any category of covered entities, to establish government security committees similar to those required for companies that are subject to foreign ownership control or influence mitigation measures. Not later than 270 days after the date of the enactment of this Act [ Jan. 7, 2011 ], the Secretary shall submit to the Committees on Armed Services of the Senate and the House of Representatives a report on the plan developed pursuant to subsection (a) and the guidance issued pursuant to subsection (c). The report shall specifically address the rationale for the Secretary’s decision on whether or not to require covered entities, or any category of covered entities, to establish government security committees similar to those required for companies that are subject to foreign ownership control or influence mitigation measures.”

Verify at the official source: Federal legislative text

Facing this? Know exactly what happens next.

MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.

This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.